Server side cross-site scripting In dolibarr/dolibarr

Description

Cross Site Scripting vulnerability in Dolibarr ERP CRM Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions
FLAT-BQSVA – Vulnerability | Fluid Attacks Database